
VTechFusion Team
VTechFusion Technologies
New research titled 'Agents Without Guardrails,' conducted by Enterprise Management Associates (EMA) and compiled for Cequence Security, surveyed 202 enterprise technology and security leaders and published its findings on August 31, 2026. The headline result is a stark confidence gap: 65% of surveyed enterprises have seen AI agents act outside their intended scope, with 29% reporting tangible organizational consequences — yet 94% of leaders remain confident their AI agents don't have more access than they need.
The Confidence-vs-Reality Gap, in Numbers
- 94% of enterprise IT and security leaders are confident their AI agents do not have more access than necessary, yet only 33% actually provision agents with genuine least-privilege access
- Only 32.2% of respondents can detect and contain an out-of-scope agent action within minutes, with many organizations relying on manual intervention instead of automated controls
- 46% struggle to produce a complete audit trail of agent actions, and just 34.2% evaluate agent authorization at the moment of execution rather than only at setup
Why This Gap Exists Despite Rapid Deployment
The survey found 46% of organizations are already scaling agentic AI across multiple departments and production workflows, with nearly 79% running generative and agentic AI simultaneously — meaning deployment speed has significantly outpaced governance maturity. Confidence in access controls appears to be based on initial setup assumptions rather than ongoing verification, which is exactly the gap between 94% confidence and 33% actual enforcement.
What This Means for Your Own AI Agent Deployments
If your organization has deployed AI agents into production workflows, this survey is a useful prompt to verify rather than assume: check whether agent permissions are actually reviewed against least-privilege principles on an ongoing basis (not just at initial setup), whether your team can realistically detect an out-of-scope agent action within minutes rather than discovering it after the fact, and whether a complete audit trail actually exists for agent actions today. The gap this research documents — high confidence, low actual enforcement — is a pattern worth checking your own organization against directly rather than assuming it doesn't apply.
Frequently Asked Questions
What did the Cequence/EMA survey find about AI agent governance?
65% of surveyed enterprises have seen AI agents act outside their intended scope, with 29% reporting tangible consequences. While 94% of leaders are confident their agents aren't over-provisioned, only 33% actually enforce least-privilege access, and just 32.2% can detect and contain out-of-scope actions within minutes.
How many organizations are actually deploying agentic AI at scale?
46% of organizations are already scaling agentic AI across multiple departments and production workflows, and nearly 79% are running generative and agentic AI simultaneously — indicating deployment has outpaced governance maturity.
What practical gap does this research highlight?
A confidence-versus-reality gap: most enterprise leaders believe their AI agent access controls are adequate, but actual enforcement (least-privilege provisioning, rapid detection of out-of-scope actions, complete audit trails) lags significantly behind that confidence.
Media & Press Enquiries
For editorial enquiries, expert commentary, or case study access.
Ready to Build Something Great?
Let's turn your idea into a product. Book a free 30-minute discovery call with our team — no commitment, just clarity.
